Studio open until 22 October
Verification for Discord servers

A verification bot you can read step by step.

If your server used Double Counter, or you are choosing a verification bot for the first time, this is exactly what Qreate does when someone joins, what it keeps, and what it does not promise.

Member accepts the rules screen
Private message with a Verify button
One-time link on qreate.gg
Cloudflare Turnstile check
Verified role granted

Why servers are switching

On 4 October 2026 Double Counter reported that an old server it no longer used, but had left running, was breached. Its bot token was taken and used to post attacker invites in about fifty servers.

One bot, wide permissions

A stolen bot token is as powerful as the permissions the bot holds. A verification bot should hold only what verification needs.

Members left exposed

Anyone who verified through that bot may now receive phishing that uses their username or email.

Nothing to read

Many verification bots do not say what they record. You should be able to find that out before you add one.

What Qreate Verification does

A short chain with a log at the end, and two optional checks you turn on yourself.

The link works once

The verification link expires and stops working after it has been used. A failed check is counted, and the role is not granted without a pass.

Optional checks, off by default

Checks for repeat accounts and for proxies are available. Each can warn your moderators or hold the member for manual review. If the proxy check cannot run, the member is not locked out and your moderators are told.

A log your staff can read

Every attempt is logged. When a moderator approves someone by hand, it is recorded as a manual approval, not as a passed check.

What an attempt records

Each attempt records a signal derived from the member's connection, some signals from their browser, and the times involved, whether or not the optional checks are on. Qreate does not publish a retention period yet, because it has not set one it is willing to promise. When it does, the docs will say so with the date it applies from.

What we do not claim

Qreate cannot promise it will never be breached, and we have not compared how much data we keep with other bots. The AI guard in the moderation module is separate from verification: it reads messages and images once members are on your server, and it does not read messages from other bots.

Read how verification works

Frequently asked questions

Can I move without leaving my server unprotected?

Yes, if you switch in order. Turn on Qreate Verification and rules screening, set the verified role and channel permissions, test the whole path with a second account, and only then remove the old bot.

Do my already verified members have to verify again?

No. Members who already hold your verified role keep it. Nothing is imported from the old bot, and only new arrivals go through the new flow.

Does the AI guard check who is verified?

No. Verification is the one-time link, the Turnstile check and the optional rules, with no AI model in the loop. The AI guard is an opt-in moderation feature for messages and images.

Will you contact members from leaked data?

No. We do not use leaked data for anything, and we will not contact anyone because their details appeared in a breach.

Will Qreate promise that data cannot leak?

No. We tell you what a verification attempt records and that we have not set a retention period, so you can decide for yourself.

Sources on the incident

We link the primary reports instead of summarising them for you.

Tell Q what your server needs.

Studio access is open free until 22 October 2026 with no credit card required. A permanent free plan remains available. Paid plans will be announced separately.

From the blog

All articles